Extension WordPress
Vulnérabilités Global Flash Gallery
Cette page rassemble les failles publiées pour Global Flash Gallery, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Global Flash Gallery
3 fiches
Global Flash Gallery <= 0.15.1 – SQL Injection
The Global Flash Gallery plugin for WordPress is vulnerable to generic SQL Injection via the ‘popup.php id' parameter in versions up to, and including, 0.15.2 due to insufficient escaping on the user supplied parameter and lack of sufficient…
*-0.15.1
0.15.2
01/08/2014
Global Flash Gallery < 0.13.4 – Cross-Site Scripting
The Global Flash Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 0.13.3 due to inclusion of a vulnerable version of jPlayer. This makes it possible for unauthenticated attackers to inject…
*-0.13.3
0.13.4
25/05/2014
Global Flash Gallery <= 0.15.1 – Arbitrary File Upload
The Global Flash Gallery Plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the /global-flash-galleries/swfupload.php file in versions up to, and including, 0.15.1. This makes it possible for unauthenticated attackers to…
*-0.15.1
0.15.2
08/09/2011
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.